not-wlan / instrumentation-callbacksView external linksLinks
based on https://github.com/secrary/Hooking-via-InstrumentationCallback
☆73Oct 29, 2019Updated 6 years ago
Alternatives and similar repositories for instrumentation-callbacks
Users that are interested in instrumentation-callbacks are comparing it to the libraries listed below
Sorting:
- codes for my blog post: https://secrary.com/Random/InstrumentationCallback/☆183Nov 30, 2017Updated 8 years ago
- ☆17Dec 18, 2022Updated 3 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆153Nov 14, 2021Updated 4 years ago
- Simple DLL and client app that work together to hook all the functions in WinHvPlatform.dll in order to provide logging and introspection…☆21Dec 1, 2021Updated 4 years ago
- eac memory sig maker☆14Jun 10, 2021Updated 4 years ago
- detect hypervisor with Nmi Callback☆42Sep 25, 2022Updated 3 years ago
- A Simple Example☆23Nov 30, 2018Updated 7 years ago
- How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver☆26May 29, 2023Updated 2 years ago
- PTE hook☆33Jun 15, 2024Updated last year
- ☆159May 21, 2024Updated last year
- ☆23Jul 24, 2023Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆53Apr 7, 2022Updated 3 years ago
- page table manipulation to gain physical r/w☆43May 7, 2024Updated last year
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 3 years ago
- base for testing☆186Sep 28, 2024Updated last year
- hidden_syscall - syscaller without using syscall instruction in code☆62Jan 23, 2023Updated 3 years ago
- Communication via callback☆73Oct 9, 2019Updated 6 years ago
- a dumb rpm/wpm example driver☆15Jun 7, 2021Updated 4 years ago
- ☆15Feb 5, 2021Updated 5 years ago
- Hijack NotifyRoutine for a kernelmode thread☆41Jun 4, 2022Updated 3 years ago
- mouseclassservicecallback detection via hook☆52Feb 7, 2022Updated 4 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆234Apr 2, 2022Updated 3 years ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆163Jul 31, 2022Updated 3 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆32Dec 31, 2024Updated last year
- ☆223Mar 11, 2023Updated 2 years ago
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆53May 23, 2022Updated 3 years ago
- ☆23Oct 28, 2020Updated 5 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆192Jul 11, 2023Updated 2 years ago
- BattlEye x64 usermode injector☆66Mar 20, 2019Updated 6 years ago
- POC usermode <=> kernel communication via ALPC.☆70Jun 6, 2024Updated last year
- ☆144Dec 10, 2022Updated 3 years ago
- PoC capable of detecting manual syscalls from usermode.☆206Nov 13, 2025Updated 3 months ago
- Windows kernel drivers simple HTTP library for modern C++☆40Jul 12, 2018Updated 7 years ago
- KSOCKET provides a very basic example how to make a network connections in the Windows Driver by using WSK☆541Sep 2, 2022Updated 3 years ago
- Windows Manipulation Library (x64, User/Kernelmode)☆77Oct 4, 2018Updated 7 years ago
- This tool will allow you to spoof the return addresses of your functions as well as system functions.☆541Nov 12, 2022Updated 3 years ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 3 years ago
- Hooking SSDT with Avast Internet Security Hypervisor☆115Apr 6, 2019Updated 6 years ago